Firewall/iproute query


Has anyone done something like this before ? I've checked the
Netfilter/iptables FAQ's and the iproute2/policy routing documentation, but
no-one seems to have done anything exactly like this before.

I have a managed server on the internet, IP address a.b.c.d, and it needs to
connect to another managed server, somewhere else on the internet, with
public address w.x.y.z. The server w.x.y.z is behind a router and firewall
(F), running Fedora 6. All well and good, I can connect on the ports I

However, to provide some redundancy, I've got two different ISP's coming
into the firewall F, call them A and B. I've put several network cards in
w.x.y.z, configured one for ISP A and ISP B, and I can connect via ISP A to
w.x.y.z when I make the default route to the appropriate network A, and
similarly with connection via ISP B when the default route from w.x.y.z is
via the appropriate network B.

What I'd like to do is NAT or smart policy routing so that I can route to
server w.x.y.z via an ISP of choice from a.b.c.d without restarting networks
adding/removing routes etc. Ideally, I'd like to load balance so, for
example traffic for port xxxx goes via ISP A and traffic for port yyyy goes
via ISP B in real time. Or even the same port on a round-robin basis.

When we try this and do some packet analysis, it seems that with ISP A as
the default gateway on server w.x.y.z, packets sent via ISP B are received
at w.x.y.z, but the replies destined for a.b.c.d are routed to ISP A.

Any thoughts ? Is this even possible ?

Hope the description makes sense.



Alan Wilson | Icetrak Ltd | v 0845 456 0561 | f: 0870 889 5005 | w:

redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe

Relevant Pages

  • Re: Outgoing POP3 email missing/lost/not received
    ... Funny thing is that I have had this ISP for 8 years and it has always been ... It looks like when you last ran CEICW, you set the ISP's mail server to: ... Internet Connection Wizard. ... After the wizard completes, the following network connection ...
  • Re: Two Networks on one System
    ... This does not depend on the route the client takes, ... depending on the ISP. ... All clients from ISP A will come to your public IP directly, ... Traffic to public IP A has a reply-to to the ISP's router in network A. ...
  • Re: ISA Is Driving Me Insane!
    ... another ISP in my area and they only provide PPPoA connections. ... no changes to their network and Radius authentication schemes. ... I have an ISA server configured in a 3 legged configuration so I ... to get all my published servers on the perimeter network. ...
  • Re: Running own mail server
    ... The ISP I'm going with gives out free static IP addresses. ... I'm pretty sure I can get the sendmail part sorted, but DNS has me confused. ... Get your DNS set up and check that you can "find yourself" from outside your own network. ... The internet police will not swoop down on you if you don't but your network disappears whenever your name server is down. ...
  • Re: Cam Setup
    ... I have to enable uPnP in my router and use a web server provided by Panasonic to provide a fixed IP address so I can access the cam from anywhere. ... Your ISP has a Terms of Service. ... Operating a "server" on your home LAN, port forwarding ...